Dynamic Security Insertion in Virtualized Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional network security devices are ineffective in virtualized network environments as they rely on physical interconnections and communication protocols, failing to provide adequate security in segregated virtual networks.

Innovation Solution

A system architecture that includes a control server and network devices implementing network virtualization protocols like OpenFlow and SDN, which separates packet forwarding and routing decisions, using flow tables to enforce centralized security and policy-based routing decisions across virtualized networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional network security devices are used in virtualized networks, then physical network security can be maintained, but security effectiveness deteriorates in virtual network environments

Engineering Contradiction:
Improvenetwork security effectivenessVSAvoidcompatibility with virtualized networks
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a virtual network security device as an intermediary component that operates within the virtualized network environment. This security device acts as a mediator between the physical network infrastructure and virtual network traffic, enabling security functions to be applied to virtual networks without requiring changes to physical network devices. The virtual security device intercepts and inspects virtual network traffic, applying security policies specific to virtual network segments.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces traditional physical network security devices with software-based virtual network security devices. Instead of relying on hardware appliances that enforce security at the physical layer, the system uses virtualized security functions that can be dynamically deployed and configured within the virtual network environment. This substitution allows security to follow the traffic regardless of its physical path.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Adaptability or versatility

If network virtualization is implemented, then network resource utilization and flexibility improve, but network security management complexity increases

Engineering Contradiction:
Improvenetwork virtualization capabilityVSAvoidsecurity management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges security management functions with the virtual network controller. By integrating security policies and enforcement mechanisms into the existing virtual network management architecture, the system avoids creating separate complex security management layers. The virtual network controller simultaneously handles both network virtualization operations and security policy enforcement, simplifying overall management.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a universal virtual network security device that can serve multiple virtual network segments and enforce various security policies through a single platform. This multi-functional security device can handle different types of security requirements (firewall, intrusion detection, access control) across multiple virtual networks, reducing the need for separate security systems for each virtual network.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9258275B2System and method for dynamic security insertion in network virtualization
Publication Date: 2016.02.09 GRYPHO5 LLC
  • US9258275B2 patent drawing
  • US9258275B2 patent drawing
  • US9258275B2 patent drawing

AI summary

A method and apparatus for dynamic security insertion into virtualized networks is described. The method may include receiving, at a network device from a second network device, a data packet and application data extracted from the data packet. The method may also include generating a routing decision for a network connection associated with the data packet based, at least in part, on the application data. Furthermore, the method may include transmitting the routing decision for the data packet to the second device for the second device to route the data based on the routing decision.